Nzyme 1.2.0 is available, a toolkit for tracking attacks on wireless networks.

The Nzyme 1.2.0 toolkit has been released, designed for monitoring wireless network traffic to detect malicious activity, deployed rogue access points, unauthorized connections, and typical attacks. The project code is written in Java and is distributed under the SSPL (Server Side Public License), which is based on AGPLv3 but is not open due to discriminatory requirements regarding its use in cloud services.

Traffic capture is achieved by switching the wireless adapter to monitor mode for transit network frames. It is possible to forward captured network frames to the Graylog system for long-term storage in case the data is needed for incident analysis and malicious actions. For example, the program allows the detection of unauthorized access points, and if a compromise attempt is identified on the wireless network, it will show who the target of the attack was and which users were compromised.

The system can generate several types of alerts and supports various methods of detecting anomalous activity, including checking network components via fingerprint identifiers and creating traps. Alerts can be generated for violations of network structure (for example, the appearance of an unknown BSSID), changes to security-related network parameters (such as changes in encryption modes), detection of typical devices used for attacks (like WiFi Pineapple), logging access to traps, or identifying anomalous changes in behavior (for example, the presence of individual frames with an atypically low signal strength or breaches of packet intensity thresholds).

In addition to analyzing malicious activity, the system can be used for general monitoring of wireless networks, as well as for physically locating the sources of identified anomalies by using trackers that can pinpoint malicious wireless devices based on their specific attributes and signal level changes. Management is performed through a web interface.

Nzyme 1.2.0 is available, a toolkit for tracking attacks on wireless networks.

In the new version:

  • Added support for generating and sending email reports on identified anomalies recorded in networks and overall status.
    Nzyme 1.2.0 is available, a toolkit for tracking attacks on wireless networks.
  • Added support for alerts about attempts to launch attacks that could disrupt the operation of surveillance cameras, based on mass deauthentication packet transmissions.
  • Added support for alerts regarding the detection of previously unseen SSID identifiers.
  • Added support for alerts about failures in the monitoring system, for example, when the wireless adapter is disconnected from the computer running Nzyme.
  • Improved compatibility with WPA3-based networks.
  • Added the capability to define callback handlers to respond to alerts (e.g., for logging anomaly information in a log file).
  • Added an inventory list of resources displaying the parameters of deployed networks being monitored.
    Nzyme 1.2.0 is available, a toolkit for tracking attacks on wireless networks.
  • Added a page with the attacker's profile, providing information about the systems and access points interacted with by the attacker, as well as statistics on signal strength and sent frames.
    Nzyme 1.2.0 is available, a toolkit for tracking attacks on wireless networks.


    Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster